Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Cyber Resilience Engineer

  • 28 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Designs cyber resilience: RTO/RPO architecture, immutable backup and restore validation, ransomware playbooks, and security-focused chaos testing.

About

An agent skill for engineering and operating cyber resilience, covering RTO/RPO architecture, immutable backup and restore validation, dependency mapping, ransomware and destructive-malware playbooks, and security chaos testing. A developer uses it when designing recovery objectives, validating restores, or sustaining continuity during active attacks.

  • Immutable backup patterns and restore validation with evidence
  • Crisis playbooks for ransomware and cloud control-plane loss, aligned to NIST CSF Recover

Cyber Resilience Engineer by the numbers

  • 28 all-time installs (skills.sh)
  • Ranked #1,509 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill cyber-resilience-engineer

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs28
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Designs cyber resilience: RTO/RPO architecture, immutable backup and restore validation, ransomware playbooks, and security-focused chaos testing.

Files

SKILL.mdMarkdownGitHub ↗

Cyber Resilience Engineer

When to Use

  • Define RTO/RPO and recovery tiers for production, security, and identity services
  • Design backup, restore, and immutability architecture (object lock, air-gap, WORM, vault isolation)
  • Map critical service dependencies and failure domains for continuity during attacks
  • Author attack-scenario playbooks (ransomware, wiper, IdP loss, logging blind spot, cloud control-plane)
  • Plan and run resilience tests—restore drills, game days, chaos/failure injection with pass/fail evidence
  • Align engineering deliverables with NIST CSF Recover and BCM/IR interfaces
  • Produce resilience metrics and engineering briefs for leadership and audit consumers

When NOT to Use

  • Own enterprise BCM program, BIA facilitation, and regulatory BCM policy → bcm-disaster-recovery-specialist
  • Lead active incident war room, containment, and forensic preservation → incident-responder
  • Define SEV matrices, paging policy, and status-page program → incident-management-engineer
  • Operate SLIs, SLOs, error budgets, and capacity toil without recovery design → site-reliability-engineer
  • Execute ticket-level snapshots and restores without resilience architecture → cloud-system-administrator
  • Control-by-control audit evidence and framework mapping only → compliance-specialist
  • Board-level security strategy and risk appetite without engineering recovery → chief-information-security-officer
  • Broad security program ownership without resilience engineering → cybersecurity
  • Greenfield cloud landing zone without recovery lens → cloud-engineer (pair for placement; you own RTO/RPO fit)

Related skills

NeedSkill
BCM/DR program, BIA, tabletops, crisis comms cadencebcm-disaster-recovery-specialist
Active CSIRT response, containment, timelinesincident-responder
Incident program, SEV, on-call, postmortem processincident-management-engineer
SLO impact, reliability mitigation, error budgetssite-reliability-engineer
Backup/restore execution, snapshots, operational hygienecloud-system-administrator
SIEM/EDR/IdP/KMS implementation and hardeninginformation-security-engineer
Security program, IR policy, executive narrativescybersecurity
CISO strategy, board reporting, risk appetitechief-information-security-officer
Cloud architecture, DR regions, service selectioncloud-engineer

Core Workflows

1. Scope and engineering charter

Clarify resilience boundaries, ownership, and interfaces with BCM, IR, SRE, and platform teams.

See `references/cyber_resilience_scope.md`.

2. Recovery objectives and tiers

Set RTO/RPO, tiering, and recovery strategies with explicit trade-offs and test hooks.

See `references/recovery_objectives_and_tiers.md`.

3. Backup, restore, and immutability

Design backup topology, isolation, encryption, and restore validation for cyber events.

See `references/backup_restore_and_immutability.md`.

4. Resilience testing and chaos

Plan game days, restore drills, and controlled failure injection with evidence and remediation.

See `references/resilience_testing_and_chaos.md`.

5. Attack scenarios and playbooks

Engineer playbooks for ransomware, destructive malware, identity and logging loss, and cloud control-plane failure.

See `references/attack_scenarios_and_playbooks.md`.

6. Metrics, reporting, and governance

Track RTA vs RTO, restore success, test coverage, and NIST CSF Recover alignment for stakeholders.

See `references/metrics_reporting_and_governance.md`.

Outputs

  • Resilience architecture — tiers, dependencies, backup/immutability design, failure domains
  • RTO/RPO register — per service with strategy, owner, last test, and known gaps
  • Playbook pack — attack-scenario sequences with decision gates and IR handoffs
  • Test report — scope, RTA/RPO achieved, integrity checks, findings, remediation backlog
  • Chaos/game-day summary — hypothesis, blast radius, controls validated, follow-ups
  • Resilience dashboard brief — KPIs, trend, top risks (engineering lens; not legal advice)

Principles

  • Engineer for compromise — assume attacker presence; prefer rebuild and immutable recovery paths
  • Test restores, not jobs — backup success ≠ recoverable; measure RTA and data integrity
  • Recover security first — identity, logging, and detection before convenience workloads
  • Separate roles — resilience engineering complements BCM policy and IR command
  • Evidence by design — every tier and playbook links to a test or exercise with dated results

Related skills

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.